The goal of the OWASP AJAX Security project is to identify and document security issues encountered by AJAX applications and document ways to secure these applications. The OWASP AJAX Security project is being lead by Anurag Agarwal.

We are actively seeking contributors to add new sections . If you are interested in volunteering for the project, or have a comment, question, or suggestion, please drop me a line mailto:rohini_sulatycki@yahoo.com<br>We are currently working on the Ajax Literature Review so if you have any good books/arcticles/presentations that you think should be included let us know. Also if you are interested in working on new sub-projects such as creating a guide on Ajax frameworks/tools or have ideas for a project then email us.

+

We are actively seeking contributors to add new sections . If you are interested in volunteering for the project, or have a comment, question, or suggestion, please drop me a line mailto:abraham_kang[at]yahoo.com<br> Also if you have an idea for new sub-projects then email us.

'''Update:''' We have a new volunteer Vishal Garg. Many thanks to Vishal!

'''Update:''' We have a new volunteer Vishal Garg. Many thanks to Vishal!

== Current Project Status ==

== Current Project Status ==

−

We are currently working on reviewing Ajax frameworks/tools. The intent of the review is to provide an overview of the framework, the security risks and how the frameworks can be secured.

+

We are currently working on reviewing Ajax frameworks/tools. The intent of the review is to provide an overview of the framework and the security issues handled by the framework.

−

The framework we are currently reviewing is the Google Web Toolkit[[https://www.owasp.org/index.php/Google_Web_Toolkit]]. If you have experience using GWT and/or are interested in participating in this review please contact us either though the mailing list or emailing Rohini

+

The framework we are currently reviewing is the '''Google Web Toolkit'''[[https://www.owasp.org/index.php/Google_Web_Toolkit]]. If you have experience using GWT and/or are interested in participating in this review please contact us either though the mailing list or emailing anurag.agarwal[at]yahoo.com

== Updates ==

== Updates ==

Line 24:

Line 29:

The SPI Dynamics presentation from BlackHat 2007 can be viewed here [https://www.blackhat.com/presentations/bh-usa-07/Sullivan_and_Hoffman/Whitepaper/bh-usa-07-sullivan_and_hoffman-WP.pdf ]

The SPI Dynamics presentation from BlackHat 2007 can be viewed here [https://www.blackhat.com/presentations/bh-usa-07/Sullivan_and_Hoffman/Whitepaper/bh-usa-07-sullivan_and_hoffman-WP.pdf ]

Revision as of 00:30, 27 April 2011

Main

Introduction

The goal of the OWASP AJAX Security project is to identify and document security issues encountered by AJAX applications and document ways to secure these applications. The OWASP AJAX Security project is being lead by Anurag Agarwal.

Volunteers Needed

We are actively seeking contributors to add new sections . If you are interested in volunteering for the project, or have a comment, question, or suggestion, please drop me a line mailto:abraham_kang[at]yahoo.com Also if you have an idea for new sub-projects then email us.

Update: We have a new volunteer Vishal Garg. Many thanks to Vishal!

Current Project Status

We are currently working on reviewing Ajax frameworks/tools. The intent of the review is to provide an overview of the framework and the security issues handled by the framework.

The framework we are currently reviewing is the Google Web Toolkit[[1]]. If you have experience using GWT and/or are interested in participating in this review please contact us either though the mailing list or emailing anurag.agarwal[at]yahoo.com